The Procolored Printer Software Malware

Updated 5 Oct 2026 · Incident date 1 Oct 2024 · vendor binary

PackageProcolored driver/software bundles for F8, F13, F13 Pro, V6, V11 Pro and VF13 Pro, hosted on the vendor's official download links
FileProcolored driver and utility executables in the downlo...

Software for six Procolored printer lines carried malware. The affected lines are the F8, F13, F13 Pro, V6, V11 Pro and VF13 Pro. The last infected update dated from October 2024, and Procolored removed the downloads on 8 May 2025.

The malware included the XRed backdoor and a file infector and clipboard thief named SnipVex.

What happened

A YouTuber, Cameron Coward, found malware on a USB stick that came with a UV printer from Procolored. CyberInsider reports that G Data analyst Karsten Hahn then confirmed infections in the vendor's downloadable software, about 8 GB in total.

G Data found 39 detections across 20 files with unique hashes. The infected PrintExp.exe held both payloads, which suggests the developer or build systems were compromised, according to Security Online.

The malware had three parts:

Procolored said that software moved by USB might have introduced the malware. It promised to scan all files before it uploaded them again. G Data and others advised reinstalling the operating system on affected machines.

Affected versions

The affected items are the driver and software bundles for six printer models. The sources give no version numbers.

CyberInsider reports that the last infected update was in October 2024 and that downloads came down on 8 May 2025. Any bundle you downloaded or copied from the USB stick before then needs a check.

Indicators of compromise

The Bitcoin address and marker come from the Hacker News report on this malware family. I could not confirm file hashes beyond the counts above.

How to check

Scan the printer software folder and any copied installers with your antivirus tool, and check for the detection names above. Then check for the file that G Data named.

Get-ChildItem -Path C:\ -Recurse -Filter PrintExp.exe -ErrorAction SilentlyContinue | Get-FileHash -Algorithm SHA256

Submit the hash to a malware scanning service to see whether it is flagged. Also check your antivirus exclusion list for entries you did not add. G Data advises doing this, because the vendor told users to exclude the files.

What to do now

  1. Disconnect any machine that ran Procolored software from before May 2025.
  2. Remove antivirus exclusions you did not set.
  3. Back up documents only, then reformat the machine and reinstall the operating system.
  4. Change passwords and keys that were used on that machine.
  5. Check wallets and payment addresses. The clipboard thief changed copied addresses.
  6. Do not dismiss antivirus alerts on vendor software as false positives.

Vigilance compares the version you trust with a new one and reports the file that gained a new capability. See all attacks.

What Vigilance showed

Vigilance compares the version you trust with the new one and names the file that gained a new capability. The block below is rebuilt from the public reports in the words Vigilance prints. It is not a captured scan, because the malicious release is not redistributed.

vigi diff --old Procolored-prev --new Procolored-current
files scanned: 16

HEADS UP  1 file can now do things the old version could not. The rest changed and gained nothing.

CHANGED    Procolored.exe
           It now downloads from the internet. It did not before.

Frequently asked questions

Which Procolored printers had infected software?

The F8, F13, F13 Pro, V6, V11 Pro and VF13 Pro. The last infected update was in October 2024.

What malware was in the Procolored software?

G Data found the XRed backdoor, a clipboard thief that swaps Bitcoin addresses, and a file infector called SnipVex.

Sources

  1. cyberinsider.com/procolored-printers-distributed-malware-infested-software-for-six-months/
  2. securityonline.info/snipvex-and-xred-malware-discovered-in-procolored-printer-software/
  3. thehackernews.com/2025/05/rvtools-official-site-hacked-to-deliver.html

More supply chain attacks

All 111 attacks in the library · What is a supply chain attack? · How to prevent supply chain attacks

Check the next update before you install it

Vigilance compares the version you trust with the new one. It names the one file that can now do something it could not do before.

Start Free